VezertVezert

Custom Web Portal Development Services

Designed by humans, accelerated by AI agents. Secure client, patient, and B2B portals shipped in 6–8 weeks. HIPAA, SOC2 Type II, and ISO 27001 ready.

6–8
weeks, kickoff to launch
50+
portals shipped
HIPAA
SOC2 · ISO 27001 ready
100%
senior review before merge

Why Traditional Portal Development Is Broken

Off-the-shelf portals force your team to bend to the tool. Custom portals from a traditional agency take three to six months and cost $200k or more. You wait a quarter, then a quarter again, and the login flow still doesn't do what your CFO asked for.

Meanwhile, AI builders like Bubble or Lovable lock you in, skip compliance, and ship a demo that fails your first security audit.

What AI-Native Portal Development Looks Like

Senior engineers and Claude Design working together. The AI drafts; the senior ships. You get a custom portal in 6–8 weeks with full source ownership, HIPAA and SOC2 readiness, no vendor lock.

See the six-stage workflow →

Meet the AI Agents That Build Your Portal

Five specialised agents, one senior reviewer per stage. AI handles the mechanical work. Seniors own every decision that touches compliance, architecture, or security.

01 / Agent

Research Agent

Scans 50+ competitor portals and drafts your persona matrix in hours.

  • Extracts UX patterns from public reviews and support forums
  • Drafts a persona matrix your product designer verifies with real user interviews
  • Maps personas to RBAC groups and access levels before architecture starts
senior-reviewed
02 / Agent

UX Architecture Agent

Generates user-flow diagrams and information architecture across every role.

  • Produces first-pass wireframes for every role in the portal
  • UX lead aligns flows with your CTO and maps them to security groups
  • Trims scope that does not earn its keep before a line of code is written
senior-reviewed
03 / Agent

Claude Design Agent

Ships 10–15 hi-fi screens a day against your design system.

  • Generates dashboards, tables, forms, empty states, and error states
  • Design director enforces brand tokens and WCAG 2.2 AA accessibility
  • Every screen requires human sign-off before moving to development
senior-reviewed
04 / Agent

Developer Agent

Scaffolds React/Next.js components, REST & GraphQL APIs, RBAC, SSO, and SAML.

  • Wires Storybook and drafts unit tests from component specs
  • Senior engineer refactors, validates security, and owns every API contract
  • Every PR is human-reviewed. No auth change lands without senior sign-off
senior-reviewed
05 / Agent

QA Agent

Writes Playwright end-to-end suites and accessibility sweeps nightly.

  • Generates a coverage report each night and flags regressions immediately
  • QA engineer runs a manual security audit before pen-testing begins
  • Go-live runbook is signed off by humans, not automated
senior-reviewed

Book a Discovery Call

30 minutes. We come back with a written scope, compliance posture, and price range within two business days.

Start With Discovery: $5k / 2 Weeks

Types of Web Portals We Build

Six flavours of custom portal, each with its own compliance, integration, and UX pattern library. Click a card to see the dedicated service page.

B2C / SaaS

Client Portal Development

Secure customer-facing portals for SaaS and professional services. Covers document exchange, billing, tickets, and self-service.

Partner / Reseller

B2B Portal Development

Multi-tenant portals for partners, resellers, and account managers. SSO with Okta or Azure AD, granular RBAC, order and quote workflows.

Healthcare / HIPAA

Patient Portal Development

HIPAA-ready patient portals with EHR integrations (Epic, Cerner), telehealth, secure messaging, and prescription management.

Supply Chain

Vendor Portal Development

Supplier onboarding, PO management, invoice submission, and SLA dashboards. Ready for SOX and ISO 27001 audits.

Internal / HR

Employee Portal Development

Intranets and HR portals with SSO, leave requests, knowledge bases, and integrations to Workday, BambooHR, and Slack.

AI-Native

AI-Powered Client Portal

Semantic search, chat assistants, and predictive alerts embedded in your client experience. Claude or OpenAI, with a full audit trail.

What You Get With Every Portal Project

Four phases, fixed scope, written SOW. Procurement gets a checklist; your CTO gets a shippable architecture on day one.

1

Weeks 1–2

Discovery

Problem statement, user personas, information architecture, clickable prototype, and a security and compliance plan mapped to your audit posture.

2

Weeks 3–4

Design

Design system, 15–30 hi-fi screens (Claude Design plus senior designer), clickable prototype, and a WCAG 2.2 AA accessibility audit.

3

Weeks 5–7

Build

Production code (React/Next.js plus backend), SSO/SAML, RBAC, API integrations, Playwright e2e tests, and a staging environment.

4

Week 8

Launch & Handoff

Production deploy, auto-generated plus human-reviewed documentation, a recorded knowledge transfer, and 30 days of post-launch support.

Fixed Scope. Written SOW.

Every engagement starts with a Discovery sprint. A written scope, compliance posture, and price range delivered within two business days.

Start With Discovery

Named Tools, Named Humans, No Mystery Agents

Five layers where AI pulls its weight. Beside it: the four things we refuse to automate. Together they explain why portals built on this stack pass CTO review.

01
Design Layer
Claude Design · Anthropic

UI and component generation. Design-system-aware. Every screen is reviewed by the design director against brand and WCAG 2.2 AA before sign-off.

Layer 01
02
Engineering
Custom AI Agents · Claude API

Code-scaffolding agents for React, Next.js, Node, and Go. Vendor-agnostic: Claude is primary, but any frontier LLM can slot in.

Layer 02
03
Code Review
AI-Assisted PR Review

Custom rule sets for security, accessibility, and architecture drift. Flags go to a senior engineer; the agent never merges on its own.

Layer 03
04
QA Layer
Playwright + Vitest Generation

AI generates end-to-end tests, fuzz inputs, and accessibility sweeps. A QA lead signs off the test plan before pen-testing begins.

Layer 04
05
Documentation
Auto-Generated Specs + Diagrams

Architecture decision records, API docs, and onboarding runbooks. Drafted by agents, reviewed by the tech lead, owned by you.

Layer 05

What We Don't Automate

Four decisions we keep human, with no exceptions and no overrides.

  • Tech Lead
    Architecture decisions

    Data model, tenancy, and auth topology. A human owns every load-bearing choice.

  • Senior Engineer + External Audit
    Security & compliance

    HIPAA, SOC2, and ISO reviews are run by named humans and a third-party audit firm.

  • Account Lead
    Stakeholder communication

    Roadmap calls, trade-offs, and difficult conversations with your CTO happen human-to-human.

Vezert

Ready to See the Stack in Action?

Book a 30-min discovery call and we walk you through every layer live: design, engineering, QA, and compliance. We share real architecture diagrams and audit letters from shipped portals. No slides, no sales pitch. Just the stack, explained by the engineers who built it.

AI Drafts, Senior Engineers Ship

Every line of code and every pixel of UI passes through a senior specialist review before merge. AI accelerates; it does not replace expertise. In portal work, one bug in an RBAC rule or an auth flow costs more in reputation than a two-week delay.

Machine
Step 01
AI Agent drafts

Code scaffolds, design drafts, tests, and documentation, generated in minutes, not days.

Human
Step 02
Senior Engineer ships

Every PR reviewed, refactored, and tested before merge. Architecture, security, and final design are owned by named humans.

Six Things Your CTO Will Ask, Answered

AI slop
01 / 06

Our CTO is worried about AI slop landing in production.

Every PR is reviewed and tested by a senior engineer before merge. SAST, DAST, and a human architecture sign-off are mandatory gates. We will walk your CTO through the pipeline on call one.

Vendor risk
02 / 06

What happens if Anthropic raises prices or deprecates a model?

Our architecture is vendor-agnostic. Claude is primary for design and code, but we can swap to any frontier LLM (OpenAI, Google Gemini, open-weights) without touching your portal runtime. You own the prompts and the pipeline.

Security
03 / 06

Isn't AI-generated code a security risk?

Every AI-generated line passes SAST (Semgrep, SonarQube), DAST (OWASP ZAP), a manual senior review, and (for compliance-heavy portals) an external pen-test before launch. Security is a gate, not a lane.

Pricing
04 / 06

Will AI make you cheaper, or will you just pocket the savings?

Transparent pricing: 30–40% less than a ScienceSoft-tier engagement, not 90%. The savings come from mechanical work; expertise is still the value. Our SOW itemises where AI runs and where seniors do.

Evidence
05 / 06

Show me a real AI-accelerated portal you've shipped.

Our portfolio includes a HIPAA-compliant patient portal shipped in seven weeks and a B2B vendor portal in six. Book a discovery call and we'll share the architecture and the audit letters under NDA.

Opt-out
06 / 06

We're AI-skeptic, can we opt out entirely?

Yes. A Traditional Mode is available: the same senior team, no AI agents in the loop. Cost is +25%, timeline is ×1.5. Same compliance posture, same code ownership, same humans, just a slower path.

Technology Stack

Named. Versioned. Documented. Your engineering team can own this day one.

Frontend
7 tools

We use the same stack the industry converged on (React, TypeScript, Tailwind) because it has the widest hiring pool, the deepest tooling, and years of production stability behind it. Your engineering team inherits code they already know, can extend without us, and can hire for on day one.

React
Next.js 15
TypeScript
Tailwind CSS
Radix UI
shadcn/ui
Storybook

Want the Full Stack Decision Log?

We document every technology choice and the reasoning behind it. Ask us on the discovery call.

Book a Discovery Call

Integrations We've Shipped

Not a stock partner badge wall. Actual integrations we've wired, debugged, and handed off with documentation.

StripeStripe BillingChargebeeRecurlyAdyen

Security, Compliance, and AI Governance

Six compliance postures we build and audit against. Bring your auditor: we've done this before.

1

PHI Protection

HIPAA-Ready

BAA-compatible architecture, PHI handling, encryption at rest (AES-256) and in transit (TLS 1.3), audit logs retained per your policy.

2

Security Audit

SOC2 Type II

Controls for security, availability, confidentiality, processing integrity, and privacy. We provide control narratives and evidence packs for your Type II window.

3

Info Security

ISO 27001

Information Security Management System with documented policies, risk register, access reviews, and a mapped Statement of Applicability.

4

Data Privacy

GDPR & CCPA

Data minimisation, lawful-basis tracking, right-to-erasure and data-portability flows. DPIAs written in plain English.

5

When Applicable

PCI DSS

Tokenised payment flows via Stripe or Adyen. We aim for SAQ-A scope so your portal never touches raw card data.

6

Audit & Control

AI Governance

Audit logs for every AI-generated change, model cards for each deployed AI feature, opt-out for customer-data training, and prompt-injection guardrails.

Vezert vs Traditional Agency vs AI Builder

The three real options for a custom portal in 2026. Built from our own client engagements and published pricing.

ParameterAI Builder (Bubble, Lovable)Vezert AI-NativeTraditional Agency
Time to MVP1–2 weeks (templated)6–8 weeks3–6 months
Custom design
Claude Design + SeniorManual, any scope
HIPAA / SOC2 / ISO 27001
Full if scoped
Custom backend logicPlatform-limited
Full code ownership
Price range$5k–$30k$40k–$200k$80k–$500k+
Self-hostable

Benchmarks from published pricing and our own client engagements. Builder tier reflects enterprise plans of the named platforms.

From Kickoff to Launch in 6–8 Weeks

Four phases, eight weeks, one shared project board. AI compresses the mechanical work; seniors own every decision that touches compliance or architecture.

01

Weeks 1–2 · Discovery

Paid discovery ($5k / 2 weeks). Problem statement, personas, information architecture, a security and compliance plan, and a signed SOW. Mix: 30% AI, 70% human.

1 / 5

Transparent Pricing, No Retainer Until Launch

Every portal engagement starts with a paid $5k discovery (2 weeks) that locks the scope, the compliance posture, and the price. Build projects start at $9,000 for a client portal and reach $90,000 for a fully-compliant HIPAA + SOC2 patient portal with all AI features. AI handles the mechanical work so seniors focus on security, architecture, and final review. Traditional Mode (no AI agents) is available at +25%.

Key factors that affect pricing:

  • 01Portal type: client, patient, B2B, or AI-powered
  • 02Number of user roles and permission groups
  • 03Third-party integrations (EHR, CRM, payments, SSO)
  • 04Compliance posture: standard GDPR, HIPAA, or SOC2
  • 05Optional AI features: semantic search, chat, summarisation

Portal Cost Estimator

Pick a portal type, set the shape of your use case, and see a transparent price and timeline range. The number matches what lands in your SOW within two business days of a discovery call.

live estimate
810 weeks
€12k €15k
Book a Discovery Call

Estimate is a transparent range, not a quote. Final SOW lands within two business days of a discovery call and matches this range or comes in below.

portal type
3
110
3
18
compliance tier
ai features · add-ons

How a Vezert Portal Is Put Together

Four stacked layers. The fourth (the AI layer) is optional. The first three are always yours, always self-hostable, always documented.

01
Presentation
01

What the user sees

Server-rendered React and Next.js, styled with Tailwind against a shared design system. Accessible by default, lazy-loaded below the fold.

Next.js 15React 19Tailwind CSSDesign SystemStorybook
02
Application
02

How business logic runs

REST and GraphQL APIs behind a gateway. Auth, RBAC, and audit logging live at this layer, not in the UI.

REST + GraphQLAuth0 / OktaRBACSSO / SAMLAudit Logs
03
Data
03

Where state lives

PostgreSQL with row-level security as the primary store. Redis for hot paths, S3 or GCS for objects, append-only audit logs for compliance.

PostgreSQLRedisS3 / GCSRow-Level Security
04
AI Layer
AIoptional
04

Optional intelligence

Claude or OpenAI wired through a RAG pipeline with retrieval guardrails and PII redaction. Every prompt and response is logged for audit.

Claude / OpenAI APIRAG PipelineVector DB (Pinecone / pgvector)ModerationPII Redaction

Ready to Scope Your Portal?

Book a 30-minute discovery call and we'll come back with a written scope, price, and timeline within two business days. No email gate, no drip sequence.

Web Portal Development Insights

Practical guides on portal architecture, scalability, and enterprise web development.

Explore All Articles

Frequently Asked Questions

The questions we hear most on the first call. If yours isn't here, drop it in the discovery form below. We reply in one business day.